Back

Government Cloud Investigations Analyst - CTJ - Secret

YammerRedmond, WA, USA
You will be redirected to the main website
Posted on: 04 Oct 2026

Job Description

1. Investigations & Analysis Conduct deep-dive investigations into: Fraud-from-birth tenants, account compromise, abuse of government cloud resources Insider risk, misuse of privileged access, and policy violations within regulated environments Correlate signals across identity, billing, telemetry, and cross-tenant activity to reconstruct attack timelines and determine root cause Differentiate fraud vs. compromise vs. legitimate activity using structured decision frameworks and evidence correlation Provide executive-ready risk assessments and case summaries for high-visibility incidents Ensure SLA adherence (time-to-contain, response timelines, throughput) Process, Policy & Continuous Improvement Develop and refine Standard Operating Procedures (SOPs) Ensure consistent application of: Work across: Engineering (detections, telemetry, automation) Legal & Compliance (regulatory alignment, enforcement authority) Government stakeholders (data governance, access, escalation) Act as a subject matter expert (SME) for fraud investigations within Government cloud environments Must be eligible for and complete CJIS background investigation and ongoing screening requirements FedRAMP High authorization requirements DoD Cloud Computing Security Requirements Guide (SRG) (IL2-IL5/6 as applicable) NIST 800-53 controls and security frameworks Auditability and traceability in all investigative actions Doctorate in Statistics, Mathematics, Computer Science, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR equivalent experience. These requirements include, but are not limited to the following specialized security screenings: The successful candidate must have an active U.S. Government Secret Security Clearance. Failure to maintain or obtain the appropriate clearance and/or customer screening requirements may result in employment action up to and including termination. Clearance Verification: This position requires successful verification of the stated security clearance to meet federal government customer requirements. You will be asked to provide clearance verification information prior to an offer of employment. Citizenship & Citizenship Verification: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance. Criminal Justice Information Services: This position requires passing a background check conducted through the CJIS criminal justice information system by authorized local, state, and/or federal agencies. Security operations, fraud investigations, or incident response Cloud environments (Azure, M365, identity systems) Experience with investigation tooling, logs, and telemetry systems Evidence-based decision making and analytical rigor Ability to operate in: Must be a United States Citizen Required to support Government cloud environments and access regulated data Azure Government, GCC High, or DoD environments CJIS Security Policy Government incident response procedures
Government Cloud Investigations Analyst - CTJ - SecretYammer